In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)
2021-11-01T10:15:11.307
2024-11-21T05:58:21.967
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | dolphinscheduler | < 1.3.6 | Yes |